Malware

Doina.47690 (file analysis)

Malware Removal

The Doina.47690 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.47690 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Spanish (Argentina)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Doina.47690?


File Info:

name: 921D7EEE00305F9A47AD.mlw
path: /opt/CAPEv2/storage/binaries/ea2c6b5904d08096cb28d10b171ceefd919eedde897548e513b07a8f7cdc3432
crc32: F361A592
md5: 921d7eee00305f9a47ada49229db9cc8
sha1: 0c1aa09293f0b1a19418d97dd13239c331b83309
sha256: ea2c6b5904d08096cb28d10b171ceefd919eedde897548e513b07a8f7cdc3432
sha512: ee31935fae3f5feb6ea06e367ec35a18817ad28b46a88c09e676b8988a8be51dd9057319b95e8754aefbcc436d6a43d9d15786a1203d7959a043aee89058adf6
ssdeep: 49152:GbngUmOQR1dmUVlt05EO+NAmqWP/IQm0LiG5FanzP:GbngUvQdmUF05E/Amq+/IQm0LiG5+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BC52223F9D9B58DEA41D4342E347673A933E63148318E5FB394BAD71E7118262A834F
sha3_384: 27a218193643bb476d5409d14d0ce7d9bfdae8bc04b1c3274ae8a9cf777e3c25f3100647acbb84877630bf00a5f8456d
ep_bytes: 6890214000e8eeffffff000000000000
timestamp: 2020-05-20 14:58:50

Version Info:

Translation: 0x0c0a 0x04b0
CompanyName: MHLM
LegalCopyright: MHLM
ProductName: ACTU
FileVersion: 1.00
ProductVersion: 1.00
InternalName: SIDOM_ver684_win_NOXP_V3
OriginalFilename: SIDOM_ver684_win_NOXP_V3.exe

Doina.47690 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ymacco.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Doina.47690
FireEyeGen:Variant.Doina.47690
CAT-QuickHealPUA.YmaccoVMF.S20098959
SkyhighBehavesLike.Win32.Trojan.vc
McAfeeArtemis!921D7EEE0030
Cylanceunsafe
SangforTrojan.Win32.Ymacco.V2w2
APEXMalicious
BitDefenderGen:Variant.Doina.47690
AvastWin32:Malware-gen
VIPREGen:Variant.Doina.47690
EmsisoftGen:Variant.Doina.47690 (B)
MAXmalware (ai score=82)
GDataGen:Variant.Doina.47690
VaristW32/ABTrojan.CVMZ-8827
Antiy-AVLGrayWare/Win32.Ymacco
ArcabitTrojan.Doina.DBA4A
MicrosoftProgram:Win32/Ymacco.AAEA
CynetMalicious (score: 100)
VBA32BScope.Trojan.Zpevdo
ALYacGen:Variant.Doina.47690
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002H09B424
RisingMalware.Ymacco!8.11C01 (CLOUD)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.109675893.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Doina.47690?

Doina.47690 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment